Summary: If WHM or cPanel won't load or won't accept your login, work through these checks: the right address and port, a blocked IP address, the password, and browser SSL warnings.

Step 1: Check the address and port

LoginAddress
WHM (you, as root)https://YOUR-SERVER-IP:2087 or https://your-hostname:2087
cPanel (client accounts)https://YOUR-SERVER-IP:2083, https://clientdomain.com:2083, or https://cpanel.clientdomain.com
  • Make sure you're using https:// and the correct port. WHM uses 2087 and cPanel uses 2083.
  • Your server's IP and hostname are in your welcome email and in the Liberation Client Area under Services.
  • Some office, hotel, and public Wi-Fi networks block ports 2083 and 2087. Try another network, such as your phone's hotspot. Clients can also try https://cpanel.clientdomain.com, which uses the standard HTTPS port.

Step 2: Is your IP address blocked?

Your server protects itself from password-guessing attacks. After several failed logins, it can block the IP address they came from.

  • The page times out or never loads, but works from another network: the Imunify360 firewall has probably blocked your IP.
  • The page loads, but you see a brute-force or "too many failed attempts" message: cPHulk has probably locked the login.

How to unblock

  1. Find the blocked public IP address by searching "what is my IP" from the affected computer or network.
  2. Connect to WHM from a different network, for example a phone hotspot.
  3. Imunify360: Go to Plugins » Imunify360 » Firewall. Remove the IP from the Black List or Gray List. If it's a trusted IP, add it to the White List.
  4. cPHulk: Go to Security Center » cPHulk Brute Force Protection. Check the history and blocked lists, remove the IP, and add trusted IPs to the whitelist.
  5. Wait a minute, then try again from the original network.

If you can't get into WHM from any network, open a ticket with the IP address to unblock. We'll clear it for you.

Step 3: Check the password

  • Your WHM root password is separate from your Liberation Client Area password. If you changed it after your welcome email and no longer have it, open a ticket and we'll help you regain access.
  • A client's cPanel password: Reset it in WHM under Account Functions » Password Modification. Then send the new password to your client through a secure channel.
  • Your Liberation Client Area password: Use the password reset link on the Client Area login page.
  • Type the password by hand, or paste it without extra spaces at the start or end. If your password manager fills in the wrong saved login, delete the old entry.

Step 4: Browser security warning

If you log in with your server's IP address, your browser may show "Your connection is not private" or a similar warning. This happens because SSL certificates are issued for names like your hostname, not for bare IP addresses.

  • If you typed the IP address from your welcome email, it's safe to continue past the warning.
  • For a warning-free login, set a proper hostname, such as server1.yourbrand.com, point it at your server's IP, and log in at https://server1.yourbrand.com:2087. AutoSSL can issue a certificate for the hostname once DNS resolves.
  • Never continue past a certificate warning on an address you don't recognize.

Step 5: Two-factor authentication problems

If a client loses access to their authenticator app, you can remove two-factor authentication from their cPanel account in WHM under Security Center » Two-Factor Authentication. If you're locked out of WHM itself, open a ticket.

Prevent future lockouts

  • Add your office and home IP addresses to both the Imunify360 White List and the cPHulk whitelist. If your ISP changes your IP address from time to time, update these lists when it does.
  • Use a password manager so logins are always typed correctly.
  • Remind clients that repeated failed attempts can block their whole office network.

Still stuck? Open a ticket

Our U.S.-based support team is available 24/7. Open a support ticket from the Liberation Client Area and include your server IP, the address you're trying to reach, the exact error message, and your public IP address. Tickets are private, so they are the safe place to share server details. Never post passwords in public forums or chats.

Was this answer helpful? 0 Users Found This Useful (0 Votes)